CVE-2024-4787
Cost Calculator Builder PRO <= 3.1.75 - Unauthenticated Arbitrary Email Sending
CVSS Score
5.8
EPSS Score
0.0%
EPSS Percentile
0th
The Cost Calculator Builder PRO for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 3.1.75. This is due to insufficient limitations on the email recipient and the content in the 'send_pdf' and the 'send_pdf_front' functions which are reachable via AJAX. This makes it possible for unauthenticated attackers to send emails with any content to any recipient.
| CWE | CWE-20 |
| Vendor | stylemixthemes |
| Product | cost calculator builder pro |
| Published | Jun 19, 2024 |
| Last Updated | Apr 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for stylemixthemes cost calculator builder pro
Be the first to know when new medium vulnerabilities affecting stylemixthemes cost calculator builder pro are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
StylemixThemes / Cost Calculator Builder PRO
0 ≤ 3.1.75
References
Credits
István Márton